Privacy Policy
Last Updated: January 29, 2026
Introduction
Have Adventure! ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and mobile app (collectively, the "Service").
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Authentication data: Email address, name, and profile picture (from OAuth providers like Google, Apple, Discord, GitHub, or Facebook)
- Account identifiers: Unique user ID and OAuth provider account information
- Display preferences: Display name and avatar settings
1.2 User-Generated Content
We store content you create within the Service:
- Characters: Character sheets, backstories, stats, and AI-generated avatars
- Adventures: Adventure modules, scenes, quests, NPCs, and monsters you create
- Gameplay data: Game sessions, messages, dice rolls, and party interactions
- Social features: Party memberships, invitations, favorites, and reviews
1.3 Subscription and Payment Information
We use Stripe for payment processing and store:
- Subscription data: Plan type, subscription status, start/end dates
- Payment identifiers: Stripe customer ID and subscription ID (we do NOT store credit card numbers)
- Billing history: Transaction records and payment status
1.4 Usage and Analytics Data
To improve our Service, we collect:
- Usage statistics: Feature usage, creation counts, and API interactions
- Technical data: Device type, browser type, operating system, and IP address
- Analytics: Page views, session duration, and user engagement metrics (via Google Analytics)
1.5 AI-Generated Content
When you use AI features, we:
- Send your prompts and inputs to AI providers (OpenAI and Google Vertex AI)
- Store AI-generated text, images (avatars), and structured data
- Track AI usage for billing and rate limiting purposes
2. How We Use Your Information
We use collected information to:
- Provide the Service: Enable account creation, authentication, and access to features
- Generate AI content: Create characters, adventures, and game content using AI models
- Process payments: Manage subscriptions and billing through Stripe
- Improve the Service: Analyze usage patterns, fix bugs, and develop new features
- Communicate with you: Send account updates, service notifications, and support responses
- Ensure security: Detect fraud, prevent abuse, and enforce our Terms of Service
- Comply with legal obligations: Respond to lawful requests and legal processes
3. Data Sharing and Disclosure
We do not sell your personal information. We share data only in these limited circumstances:
3.1 Service Providers
- Google Cloud Platform: Hosting and infrastructure
- Neon: Database hosting
- OpenAI and Google Vertex AI: AI content generation
- Stripe: Payment processing
- Google Analytics: Usage analytics
3.2 Public Content
Content you mark as "public" (such as published adventure modules) is visible to other users and may be featured on our platform.
3.3 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights and safety.
4. Data Security
We implement industry-standard security measures to protect your data:
- Encrypted data transmission (HTTPS/TLS)
- Secure authentication via OAuth 2.0 and JWT tokens
- Database encryption at rest
- Regular security updates and monitoring
- Access controls and audit logging
However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. You can request account deletion at any time, which will permanently remove your personal data, user-generated content, and associated records within 30 days.
Some data may be retained for legal, tax, or security purposes as required by law.
6. Your Privacy Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Data portability: Export your data in a structured format
- Opt-out: Unsubscribe from marketing communications
- Restrict processing: Limit how we use your data
To exercise these rights, contact us at haveadventureapp@gmail.com.
7. Children's Privacy
Our Service is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at haveadventureapp@gmail.com.
8. International Data Transfers
Your data may be processed and stored in the United States or other countries where our service providers operate. By using our Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Authentication: Keep you logged in (session cookies)
- Preferences: Remember your settings
- Analytics: Understand how you use the Service (Google Analytics)
- Security: Prevent fraud and abuse
You can control cookies through your browser settings, but disabling them may limit functionality.
10. Third-Party Links
Our Service may contain links to third-party websites or services (such as OAuth providers). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
13. GDPR & CCPA Rights
For European Users (GDPR): You have the right to access, rectify, erase, restrict processing, object to processing, and port your data. You may also lodge a complaint with your local data protection authority.
For California Users (CCPA): You have the right to know what personal information we collect, delete your information, and opt-out of data sales (note: we do not sell personal information).